BLOCK_READER.SYS – Worm AMN

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

BLOCK_READER.SYS – Worm AMN removal

FileMD5Virus Alias
BLOCK_READER.SYS f9aca461359daf992d72177f7559fa44 Worm AMN
BLOCK_READER.SYS f9aca461359daf992d72177f7559fa44 Trojan LdPinch

BLOCK_READER.SYS size: 1920 bytes

Created files:

%TEMP%\RarSFX0\block_reader.sys
%TEMP%\RarSFX0\HookLib.dll
%TEMP%\RarSFX0\MPR.exe
%TEMP%\RarSFX0\UpdateChecker.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\block_reader\Type: 01000000
HKLM\System\CurrentControlSet\Services\block_reader\Start: 03000000
HKLM\System\CurrentControlSet\Services\block_reader\DisplayName: MPR DRV
HKLM\System\CurrentControlSet\Services\block_reader\ImagePath: %TEMP%\RarSFX0\\block_reader.sys

Detected by UnHackMe:

BLOCK_READER.SYS
Default location: %TEMP%\RARSFX0\BLOCK_READER.SYS

Leave a Reply